Are You Who You Say You Are? Delfigo Security Can Tell From Your Typing

transmits the original username and password to the organization’s own Web servers, where the login process can proceed as usual. If the confidence score isn’t high enough, the user may be asked to type their username and password again, or to answer a pre-arranged security question (e.g. “Name your favorite flavor of ice cream”). Alternatively, the system might grant limited access, restricting users to non-sensitive areas of a company intranet, for example.

Delfigo’s software can also raise or lower the threshold that the confidence score must meet depending on additional factors such as the time of day or the location from which the user is trying to login. If you’re trying to log in at 3:00 a.m. from a building you don’t normally work in, for example, the system may require a higher confidence score before it will let you in.

But the core of the system is the keyboard-based biometric measurement, which, according to Rodriguez, draws on two decades of research on at places like IBM, SRI, and MIT showing that each computer user has a consistent typing style that is nearly as unique as their fingerprint or iris scan.

But if the science has been understood for so long, why hasn’t this form of multi-factor authentication been used before? It’s all a matter of browser technology, according to Rodriguez. “It’s only when you have the ability to use what everyone has in 2009—a sophisticated browser—that we are finally able to use the [computer power] under the cover of the browser as a toolkit to capture these electrical signals,” he says.

Companies don’t have to install any software to use Delfigo’s Software-as-a-Service technology as a gatekeeper to their systems. And Delfigo never sees the actual usernames and passwords, whose alphanumeric values are masked until a user clears the confidence threshold; it’s the dwell times and flight times that matter.

Rodriguez thinks the system will appeal to banks, hospitals, financial services companies, e-commerce companies, and any other organization with a requirement for strong authentication. “There’s an opportunity for us to replace the difficulty and the expense of token-based security,” he says.

He didn’t anticipate, however, that a healthcare organization would be his first big client. “I wish I’d been that insightful, but it only became a serious issue for healthcare when everyone started talking about electronic medical records and having different tiers of access,” Rodriguez says. “Dr. Lock is really a visionary who wanted to think through how he would deploy his own vision of providing access to hospital data to outside hospitals who don’t have that same level of sophistication [as Children’s Hospital].”

Author: Wade Roush

Between 2007 and 2014, I was a staff editor for Xconomy in Boston and San Francisco. Since 2008 I've been writing a weekly opinion/review column called VOX: The Voice of Xperience. (From 2008 to 2013 the column was known as World Wide Wade.) I've been writing about science and technology professionally since 1994. Before joining Xconomy in 2007, I was a staff member at MIT’s Technology Review from 2001 to 2006, serving as senior editor, San Francisco bureau chief, and executive editor of TechnologyReview.com. Before that, I was the Boston bureau reporter for Science, managing editor of supercomputing publications at NASA Ames Research Center, and Web editor at e-book pioneer NuvoMedia. I have a B.A. in the history of science from Harvard College and a PhD in the history and social study of science and technology from MIT. I've published articles in Science, Technology Review, IEEE Spectrum, Encyclopaedia Brittanica, Technology and Culture, Alaska Airlines Magazine, and World Business, and I've been a guest of NPR, CNN, CNBC, NECN, WGBH and the PBS NewsHour. I'm a frequent conference participant and enjoy opportunities to moderate panel discussions and on-stage chats. My personal site: waderoush.com My social media coordinates: Twitter: @wroush Facebook: facebook.com/wade.roush LinkedIn: linkedin.com/in/waderoush Google+ : google.com/+WadeRoush YouTube: youtube.com/wroush1967 Flickr: flickr.com/photos/wroush/ Pinterest: pinterest.com/waderoush/